logo

New Bluekit Phishing-as-a-Service Bypasses MFA to Steal Microsoft Login Credentials

ID: 92afaabe-319c-5601-a09d-f108dbd5b40e

STIX ID: report--92afaabe-319c-5601-a09d-f108dbd5b40e

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: Guru Baran

...
...

Bluekit is a mature Phishing-as-a-Service platform that uses a novel Browser-in-the-Middle (BitM) approach—streaming a live Microsoft login page from an attacker-controlled browser via rrweb—to harvest credentials and bypass MFA and device-bound session protections. Netcraft observed roughly 70 live hostnames, and the report details Bluekit’s layered anti-analysis techniques and recommended detection signals (WebSocket DOM streams, rrweb presence, custom CAPTCHAs, large obfuscated JS bundles, WebRTC IP mismatch) for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.